{"id":"MAL-2026-12889","summary":"Malicious code in bnpl-blocks-atom-bnpl-range (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0d1d5c6a3a1bb7d8a26a77aada7abbec439922ebceec32b8608909ad2ee8acac)\nOn require of index.js, _shim.js executes immediately and fetches an opaque binary from one of three string-concatenation-obfuscated origins (oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev) with a DNS TXT fallback under *.dl.wel1.ru. The fetched bytes are written to /tmp/.cache_\u003chex\u003e on Unix or %TEMP%\\dotnet_diag_\u003cuid\u003e.exe on Windows, chmod 0755, and spawned detached via /bin/sh -c or cmd. No hash or signature verification is performed. Hostnames, the DNS resolver domain, and the child_process module name are assembled at runtime via array-join concatenation to evade static analysis. The package name/version, masqueraded staging filename (dotnet_diag), dotfile staging path, and covert DNS-TXT fallback channel are consistent with a targeted supply-chain dropper.\n","modified":"2026-08-05T15:50:44.253506425Z","published":"2026-08-05T14:56:15Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015503","import_time":"2026-08-05T15:19:54.928803527Z","modified_time":"2026-08-05T14:56:15Z","sha256":"0d1d5c6a3a1bb7d8a26a77aada7abbec439922ebceec32b8608909ad2ee8acac","source":"amazon-inspector","versions":["35.6.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bnpl-blocks-atom-bnpl-range/v/35.6.6"}],"affected":[{"package":{"name":"bnpl-blocks-atom-bnpl-range","ecosystem":"npm","purl":"pkg:npm/bnpl-blocks-atom-bnpl-range"},"versions":["35.6.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"bnpl-blocks-atom-bnpl-range-35.6.6.tgz","hashes":{"sha1":"4aa988dc75d0123488a811cb5d1ea7400a20d2b8","sha512_sri":"sha512-tezjpFTSIL8Facz6Kzv4JMGtj5aHDcto3xxcFCwYPvZC4riChaZZDB09th3l3sz/+3plcFoiae8PTJabDoLAvw=="}}],"evidence_files":[{"path":"_shim.js","sha256":"15abd7be5dc0c2b1108045153477d821d8eff3edd1be48ed86870bed3a4f8ba8","tlsh":"b7a1a79a16ba71084bb097e4c7174816f65bf66333c0c588fb9ca5885f7252483b2efc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bnpl-blocks-atom-bnpl-range/MAL-2026-12889.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}